Content Paint

Security

Overstretched NIST to limit CVE enrichments

More than 100,000 CVE likely to be left without additional details after backlog reached breaking point.

Patch Tuesday's a monster: Thank AI?

p.s. Yes that IS a SQL injection vulnerability, in Fortinet’s FortiClient EMS, in 2026...

Adobe Reader 0day abused in wild to deliver three-stage exploit chain

Step1: An improper input sanitisation in "ANFancyAlertImpl"

Cloudflare launches WordPress competitor to fix plugin security "crisis"

Cloudflare's AI-built "successor" claims better plugin security and AI compatibility as WordPress' troubles continue.

Hugely popular npm package, Axios, compromised

“This is among the most operationally sophisticated supply chain attacks ever documented against a top-10 npm package."

“Sleeper cells” in telcos seen using novel new BPFdoor malware

"Kernel-level packet filtering to bypass multiple layers of modern network defenses"

F5 BIG-IP exploited CVE-2025-53521

Webshells seen that work in memory only

AWS Bahrain disrupted again; "Iran wiper" detected

"There is no longer a meaningful boundary between the kinetic and cyber threat surfaces."

4 KVM vendors, 9 vulns – including an unfixed CVSS 9.8

All the joy of physical-presence vulnerabilities but remotely, and many cheap, single-port IP-KVMs are wide open, says Eclypsium.

Search the site

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.